SCS-C02 Identity and Access Management Practice Question
Which THREE of the following are characteristics of IAM roles? (Choose 3.)
⚠ Common exam trap
The trap is confusing roles with IAM users, leading candidates to incorrectly believe roles have permanent credentials or require passwords, when roles actually use temporary credentials and trust policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Roles can be assumed by IAM users in another AWS account.
Option C is correct because IAM roles are designed for cross-account access: a role in Account A can have a trust policy granting the principal in Account B permission to call sts:AssumeRole, so users in another AWS account can assume it. Option D is correct because every IAM role has a trust policy (the AssumeRolePolicyDocument) that defines which principals (users, accounts, services, federated identities) are allowed to assume the role. Option E is correct because an instance profile delivers a role's temporary credentials to an EC2 instance, letting applications on that instance call AWS APIs with the role's permissions without embedding long-term keys. Option A is wrong because roles do not have long-term credentials like access keys; they issue temporary credentials via AWS STS. Option B is wrong because assuming a role uses the sts:AssumeRole API and the trust policy, not a password.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Roles have long-term credentials like access keys.
Why it's wrong here
IAM roles issue temporary security credentials via AWS STS, not long-term access keys. Unlike IAM users, roles do not have permanent access key pairs; instead, they provide ephemeral credentials with a configurable expiration, reducing the risk of credential exposure. The statement is incorrect because roles are specifically designed to avoid the need for long-lived secrets.
- ✗
Roles require a password for assumption.
Why it's wrong here
IAM roles are assumed through the AWS Security Token Service (STS) using the AssumeRole API call, which exchanges an authenticated identity for temporary credentials. A password is never involved in this process because roles are not tied to a login identity like an IAM user; instead, the trust policy defines which principals can assume the role via a token-based mechanism. Therefore, requiring a password is a fundamental misunderstanding of role assumption.
- ✓
Roles can be assumed by IAM users in another AWS account.
Why this is correct
IAM roles support cross-account access by allowing a principal from another AWS account to assume the role, provided the role's trust policy explicitly lists that account as a trusted entity. Once assumed, the principal gains the permissions attached to the role, enabling secure federation between accounts without sharing long-term credentials. This is a common pattern for centralized management or delegated administrative tasks across AWS environments.
- ✓
Roles have a trust policy that specifies who can assume the role.
Why this is correct
A role's trust policy is a JSON document that defines which entities (users, services, accounts, or external identities) are allowed to assume the role. The trust policy is a distinct component from the permissions policy, which governs what the role can do after it is assumed; the trust policy governs who can initiate the assumption. This separation is critical for fine-grained control over access delegation.
- ✓
Roles can be attached to EC2 instances to grant permissions to applications.
Why this is correct
Roles can be attached to EC2 instances via an instance profile, allowing applications running on the instance to retrieve temporary credentials from the instance metadata service (IMDSv2). This is considered a security best practice because it eliminates the need to embed access keys in code or configuration files on the instance. The AWS SDK automatically rotates the credentials, and the role's permissions are automatically enforced for any process using the instance profile.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.